DIAGNOSTIC PLAYBOOK

TLS-RPT certificate failures and policy failures need different fixes

TLS reports distinguish failure categories that can arise at different parts of delivery. A certificate problem, policy-fetch problem and MX mismatch should not be grouped into one generic encryption outage.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Read the reported policy type and failure category for the affected destination.
  2. Match the category with a direct test of the relevant HTTPS or SMTP endpoint.
  3. Assign the issue to the team controlling that endpoint and verify the exact failure condition after repair.

What this looks like

ILLUSTRATIVE EXAMPLE

A report contains a policy retrieval error and a separate expired SMTP certificate. Renewing the web certificate cannot resolve the SMTP server's expiration.

A mistake to avoid

Reports summarize observations from particular senders. Use time and destination context when comparing them with current live checks.

Keep the result in context

Transport encryption protects a connection between mail systems. It is different from message authentication and does not imply end-to-end encryption. Investigate the receiving MX hostname, the TLS session and the applicable policy separately before deciding which system needs a change.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.